
If you’ve owned a Toyota vehicle with connected services in the last several years, we have some bad news to share with you. The automaker has announced that it has discovered a major data breach on its cloud environment that has exposed the location of about 2.15 million vehicles for more than a decade. Apparently, the leak happened due to a database misconfiguration, which allowed anyone to access Toyota’s cloud environment without a password.
The firm published a security notice on its Japanese newsroom and Bleeping Computer investigated the case. Customers who used Toyota’s T-Connect G-Link, G-Link Lite, or G-BOOK services between January 2, 2012, and April 17, 2023, are affected. The exposed information includes the in-vehicle GPS navigation terminal ID number, the vehicle’s chassis number, and vehicle location information with time data.